Skip to main content
FrameworkMapper
Texas DIR Cybersecurity Framework Assessment

Texas Cybersecurity Framework Assessment

Assess your Texas K-12 district, state agency, or nonprofit against all 42 TCF control objectives using DIR's official 0-5 maturity scale — aligned to the TEA K-12 Cybersecurity Initiative methodology.

TCF
v2025-05
Texas Cybersecurity
Framework

Why This Matters

Texas K-12 Cybersecurity is Now a Funded Initiative

The TEA K-12 Cybersecurity Initiative funds EDR, MFA, DMARC, and TCF assessments through FY27. Districts that complete a structured TCF self-assessment know exactly which TEA-funded controls to prioritize.

๐Ÿ›๏ธ
$42M

FY26-FY27 TEA appropriations supporting K-12 cybersecurity, on top of $55M committed in FY24-FY25. Districts that align to TCF qualify for the most TEA-funded support.

Source: Texas Education Agency

๐Ÿ”
Crosswalk

One TCF assessment maps directly to NIST 800-53 Rev. 5, NIST CSF 2.0, and CIS Controls v8.1. A single engagement satisfies multiple framework expectations.

FrameworkMapper crosswalk dataset

๐Ÿ“‹
42

Control objectives across 5 functions (Identify, Protect, Detect, Respond, Recover). Each scored on a 0-5 maturity scale derived from CMMI / ISO 21827.

Source: DIR TCF Controls and Definitions, May 2025

๐ŸŽฏ
3.0

DIR's recommended target maturity for state agencies and the convention TEA aligns to for K-12. The assessment shows your gap from target on every objective.

Source: DIR Security Control Standards Catalog v2.1

What is the Texas Cybersecurity Framework?

TCF is the official cybersecurity framework owned by the Texas Department of Information Resources (DIR). It is mandatory for state agencies (per SB 820), public universities, junior colleges, and nonprofits accepting state funding. The Texas Education Agency operationalizes TCF for K-12 through the K-12 Cybersecurity Initiative.

42 Control Objectives

Comprehensive coverage across the legacy NIST CSF 5-function model: 11 Identify, 24 Protect, 4 Detect, 2 Respond, 1 Recover.

6-Point Maturity Scale

DIR's 0-5 scale is derived from CMMI and ISO/IEC 21827 (SSE-CMM). Districts target Level 3 (Well Defined) to align with DIR / TEA expectations.

DIR-Backed

Backed by the DIR Security Control Standards Catalog (v2.1), which is itself derived from NIST SP 800-53 Rev. 5. TCF assessments are DIR-aligned by construction.

5 Core Functions, 42 Objectives

TCF uses the legacy NIST CSF 5-function model. Each objective is independently scored on a 0-5 maturity scale.

ID

Identify

Privacy, data classification, asset inventory, policy framework, risk management, compliance, cloud security, third-party providers.

11 Objectives
PR

Protect

Awareness training, cryptography, configuration management, contingency planning, access control, identification, perimeter, content filtering, spam, DLP.

24 Objectives
DE

Detect

Vulnerability assessment, malware protection, security monitoring and event analysis, audit logging and accountability.

4 Objectives
RS

Respond

Cyber-security incident response and privacy incident response, including coordination with DIR, TEA, ESCs, and statutory notification timelines.

2 Objectives
RC

Recover

Disaster recovery procedures, including backups, restoration, alternate processing, and continuity for SIS / financial / identity systems.

1 Objective
42

Total Objectives

Each objective scored independently. The assessment surfaces gaps relative to DIR's 3.0 target so districts know exactly where to invest first.

Per DIR May 2025 revision

The DIR 0-5 Maturity Scale

Each objective is rated 0 to 5. The DIR-recommended target for state agencies and the K-12 convention TEA aligns to is Level 3 (Well Defined).

0

Not Performed

The control objective is not addressed by the organization in any meaningful way.

1

Performed Informally

Ad hoc, undocumented. Outcomes are inconsistent and depend on individual effort.

2

Planned

Planned and tracked. Procedures may exist but are not consistently followed across the organization.

3

Well Defined DIR Target

Documented, standardized, and consistently performed across the organization. The DIR-recommended target for state agencies and the K-12 alignment.

4

Quantitatively Controlled

Measured with quantitative metrics; performance is predictable and deviations are managed statistically.

5

Continuously Improving

Continuously optimized through innovation, automation, and root-cause analysis. Performance improvements are sustained.

How the Assessment Works

Walk through all 42 objectives. Score your current maturity. See the gap to target and where to invest first.

1

Set Your Scope

Identify your organization (K-12 ISD, state agency, university, nonprofit). The assessment uses K-12 target maturity by default; state-agency mode uses DIR's strict 3.0 across all objectives.

2

Score Each Objective

Walk through 11 Identify, 24 Protect, 4 Detect, 2 Respond, and 1 Recover objective. Click 0-5 to record current maturity. Each objective ships with a level-by-level rubric.

3

Review Gaps

See the function-by-function breakdown and a sortable list of every objective with its gap from target. Top-10 gaps are highlighted.

4

Generate Reports

(Phase b โ€” coming) Export a formatted TCF assessment report, a UCPA-prioritized remediation roadmap, and a multi-framework view (TCF โ†” NIST CSF 2.0 โ†” CIS Controls).

Time Estimate

A complete TCF self-assessment typically takes 2-3 hours with the rubric in front of you. Districts that have done a CIS Controls or NIST CSF assessment recently can usually finish in under 90 minutes.

What to Have Ready

  • Board-adopted security policy / acceptable use policy (TASB CQB)
  • Asset inventory (SIS, financial, identity systems first)
  • Incident response plan; vendor / third-party register
  • Status of TEA-funded controls (EDR, MFA staff email, DMARC, local admin restriction)

Sample Assessment View

Score each objective on the 0-5 maturity scale

TCF-PR-14 ยท Access Control
Restricting access to authorized users only.
0 ยท Not Performed5 ยท Continuously Improving
TCF-DE-02 ยท Malware Protection
Detection and prevention of malicious code.
0 ยท Not Performed5 ยท Continuously Improving
TCF-RS-01 ยท Cyber-Security Incident Response
Coordinated response to detected incidents.
0 ยท Not Performed5 ยท Continuously Improving

What You'll Receive

Generate reports that meet DIR methodology and translate directly to other frameworks your district may already be measured against.

TCF Assessment Report

Function-by-function maturity scoring against all 42 TCF objectives, formatted to align with DIR's expected structure. Districts can submit this to TEA / DIR or use it internally for board reporting.

  • Radar chart across 5 functions
  • All 42 objectives with current vs. target
  • DIR-aligned executive summary
Coming in Phase (b)

UCPA Remediation Roadmap

FrameworkMapper's Universal Control Prioritization Algorithm ranks every gap by impact ร— maturity-delta โ€” surfacing the objectives that move the needle the most for a typical Texas K-12 environment.

  • Ordered by impact ร— gap, not flat priority
  • TEA-funded control alignment flags
  • Tooling suggestions where inventory is known
Coming in Phase (b)

Multi-Framework View

The same evidence rendered against NIST CSF 2.0, NIST 800-53 Rev. 5, and CIS Controls v8.1. A district doing a TCF assessment effectively gets a partial CSF and CIS readout for free.

  • TCF โ†” NIST 800-53 Rev. 5 (~95% coverage)
  • TCF โ†” NIST CSF 2.0 (~90% coverage)
  • TCF โ†” CIS Controls v8.1 (~75% coverage)
Coming in Phase (b)

K-12 Specifics

Each objective is tagged for its FERPA, HB 18 (Texas Education Code ยง32.1021), and TEA initiative intersections. The K-12 view filters out objectives that don't apply to district scope.

  • FERPA + HB 18 statutory crosswalk
  • TEA-funded control alignment per objective
  • ESC partnership-friendly export
Coming in Phase (b)

Beyond Compliance

See Your Results Through an Attacker's Eyes

Completing your assessment unlocks FrameworkMapper's threat-informed views โ€” the same control scores, re-read against real adversary behavior from MITRE ATT&CK® and curated threat intelligence.

๐ŸŽฏ

Threat Lens & Adversary Likelihood

Advanced reports that map your control scores to attacker techniques and rank which adversaries are most likely to succeed against you.

๐Ÿ“„

Threat-Informed Executive Report

A board-ready PDF with your Attack Surface Coverage Score (ASCS) and kill-chain exposure, computed from your actual answers.

๐Ÿšจ

Incident Response Packet

Your assessment answers and evidence pre-fill a Responder Brief and evidence bundle, so responders can act on day one. Learn more

Included With Your Subscription

Runs on the FrameworkMapper Bundle

This assessment is part of the FrameworkMapper Bundle โ€” one per-framework subscription that also includes Gap Optimization, the Threat-Gap Visualizer, the Incident Response Packet, and progress check-ins with phone photo evidence capture, across a 12-month term.

How Pricing Works

Ready to Assess Your TCF Posture?

Start your TCF self-assessment today. Score 42 objectives, see the gap to target, and build a TEA-aligned roadmap.

Contact sales at sales@frameworkmapper.com

Where the Data Comes From

Some content on this assessment is verbatim from DIR; other content is FrameworkMapper-derived interpretive material. We label both clearly so districts, ESCs, and DIR reviewers know exactly what they are looking at.

Authoritative (from DIR)

  • Objective definitions — verbatim from the DIR TCF Controls and Definitions document, May 2025 revision.
  • Maturity scale level names and definitions (0–5) — from DIR's framework, derived from CMMI and ISO/IEC 21827 (SSE-CMM).
  • State agency target = 3.0 on every objective — DIR Security Control Standards Catalog v2.1 convention.

FrameworkMapper interpretive content

  • K-12 target maturities (a mix of 2.0 / 2.5 / 3.0 across the 42 objectives) are FrameworkMapper-recommended interim targets, reflecting realistic Texas ISD capacity given current TEA initiative scope. They are not a DIR or TEA published per-objective target. Districts wanting the strict DIR 3.0 baseline can switch the assessment to "State agency target."
  • Per-objective level-by-level rubric text — for 38 of 42 objectives the rubric language is template-generated. For 4 objectives (Access Control, Spam Filtering / DMARC, Malware Protection, Disaster Recovery) the level 3 description is hand-authored with K-12 specifics referencing TEA-funded controls. DIR's published TCF document does not include per-objective level-by-level rubrics.
  • UCPA priority scores and crosswalks to other frameworks — computed and authored by FrameworkMapper.

Full provenance for every field lives under the provenance block in the canonical tcf_v2025-05.json dataset.

Sources & Attribution

  1. Texas Department of Information Resources. Texas Cybersecurity Framework (TCF) Controls and Definitions, May 2025 revision. dir.texas.gov
  2. Texas Department of Information Resources. DIR Security Control Standards Catalog v2.1, June 2023.
  3. Texas Education Agency. K-12 Cybersecurity Initiative. tea.texas.gov